ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1518
Software Discovery
Malwaredown_new

down_new has the ability to gather information on installed applications.

T1518
Software Discovery
MalwareRedLine Stealer

RedLine Stealer can get a list of programs on the victim device.

T1518
Software Discovery
MalwareRTM

RTM can scan victim drives to look for specific banking software on the machine to determine next actions.

T1518
Software Discovery
MalwareStrelaStealer

StrelaStealer variants use COM objects to enumerate installed applications from the "AppsFolder" on victim machines.

T1518
Software Discovery
MalwareBazar

Bazar can query the Registry for installed applications.

T1518
Software Discovery
MalwareSUGARDUMP

SUGARDUMP can identify Chrome, Opera, Edge Chromium, and Firefox browsers, including version number, on a compromised host.

T1518
Software Discovery
MalwareCobalt Strike

The Cobalt Strike System Profiler can discover applications through the browser and identify the version of Java the target has.

T1518
Software Discovery
MalwareHotCroissant

HotCroissant can retrieve a list of applications from the SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths registry key.

T1518
Software Discovery
MalwareSamurai

Samurai can check for the presence and version of the .NET framework.

T1518
Software Discovery
MalwareTajMahal

TajMahal has the ability to identify the Internet Explorer (IE) version on an infected host.

T1518
Software Discovery
MalwareRaccoon Stealer

Raccoon Stealer is capable of identifying running software on victim machines.

T1518
Software Discovery
MalwareComRAT

ComRAT can check the victim's default browser to determine which process to inject its communications module into.

T1518
Software Discovery
MalwareLunarWeb

LunarWeb can list installed software on compromised systems.

T1518
Software Discovery
MalwareXCSSET

XCSSET uses ps aux with the grep command to enumerate common browsers and system processes potentially impacting XCSSET's exfiltration capabilities.

T1518
Software Discovery
MalwareQakBot

QakBot can enumerate a list of installed programs.

T1518
Software Discovery
MalwareDridex

Dridex has collected a list of installed software on the system.

T1518
Software Discovery
ToolShimRatReporter

ShimRatReporter gathered a list of installed software on the infected host.

T1518
Software Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has searched for cryptocurrency wallets on targeted hosts.

T1518.001
Security Software Discovery
CampaignKV Botnet Activity

KV Botnet Activity involved removal of security tools, as well as other identified IOT malware, from compromised devices.

T1518.001
Security Software Discovery
CampaignFrankenstein

During Frankenstein, the threat actors used WMI queries to determine if analysis tools were running on a compromised system.

T1518.001
Security Software Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors used scripts to detect security software.

T1518.001
Security Software Discovery
GroupAPT38

APT38 has identified security software, configurations, defensive tools, and sensors installed on a compromised system.

T1518.001
Security Software Discovery
GroupBlackByte

BlackByte enumerated installed security products during operations.

T1518.001
Security Software Discovery
GroupSideCopy

SideCopy uses a loader DLL file to collect AV product names from an infected host.

T1518.001
Security Software Discovery
GroupKimsuky

Kimsuky has checked for the presence of antivirus software with powershell Get-CimInstance -Namespace root/securityCenter2 – classname antivirusproduct. Kimsuky has also obtained details on antivirus software through WMI queries using `Win32_OperatingSystem` and `SecurityCenter2.AntiVirusProduct`. Kimsuky has also checked the status of Windows Defender through the use `cmd /s sc query WinDefend`.

T1518.001
Security Software Discovery
GroupPatchwork

Patchwork scanned the “Program Files” directories for a directory with the string “Total Security” (the installation path of the “360 Total Security” antivirus tool).

T1518.001
Security Software Discovery
GroupMuddyWater

MuddyWater has used malware to check running processes against a hard-coded list of security tools often used by malware researchers.

T1518.001
Security Software Discovery
GroupNaikon

Naikon uses commands such as netsh advfirewall firewall to discover local firewall settings.

T1518.001
Security Software Discovery
GroupGamaredon Group

Gamaredon Group has used PowerShell scripts to identify security software on the victim machine.

T1518.001
Security Software Discovery
GroupTeamTNT

TeamTNT has searched for security products on infected machines.

T1518.001
Security Software Discovery
GroupSidewinder

Sidewinder has used the Windows service winmgmts:\\.\root\SecurityCenter2 to check installed antivirus products.

T1518.001
Security Software Discovery
GroupRocke

Rocke used scripts which detected and uninstalled antivirus software.

T1518.001
Security Software Discovery
GroupTA2541

TA2541 has used tools to search victim systems for security products such as antivirus and firewall software.

T1518.001
Security Software Discovery
GroupTropic Trooper

Tropic Trooper can search for anti-virus software running on the system.

T1518.001
Security Software Discovery
GroupAquatic Panda

Aquatic Panda has attempted to discover third party endpoint detection and response (EDR) tools on compromised systems.

T1518.001
Security Software Discovery
GroupThe White Company

The White Company has checked for specific antivirus products on the target’s computer, including Kaspersky, Quick Heal, AVG, BitDefender, Avira, Sophos, Avast!, and ESET.

T1518.001
Security Software Discovery
GroupTurla

Turla has obtained information on security software, including security logging information that may indicate whether their malware has been detected.

T1518.001
Security Software Discovery
GroupStorm-0501

Storm-0501 has detected endpoint security solutions using `sc query sense` and `sc query windefend`.

T1518.001
Security Software Discovery
GroupMedusa Group

Medusa Group has detected security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables.

T1518.001
Security Software Discovery
GroupDarkhotel

Darkhotel has searched for anti-malware strings and anti-virus processes running on the system.

T1518.001
Security Software Discovery
GroupWindshift

Windshift has used malware to identify installed AV and commonly used forensic and malware analysis tools.

T1518.001
Security Software Discovery
GroupToddyCat

ToddyCat can determine is Kaspersky software is running on an endpoint by running `cmd /c wmic process where name="avp.exe"`.

T1518.001
Security Software Discovery
GroupMalteiro

Malteiro collects the installed antivirus on the victim machine.

T1518.001
Security Software Discovery
GroupAPT42

APT42 has used Windows Management Instrumentation (WMI) to check for anti-virus products.

T1518.001
Security Software Discovery
GroupCobalt Group

Cobalt Group used a JavaScript backdoor that is capable of collecting a list of the security solutions installed on the victim's machine.

T1518.001
Security Software Discovery
GroupWizard Spider

Wizard Spider has used WMI to identify anti-virus products installed on a victim's machine.

T1518.001
Security Software Discovery
GroupPlay

Play has used the information-stealing tool Grixba to scan for anti-virus software.

T1518.001
Security Software Discovery
GroupFIN8

FIN8 has used Registry keys to detect and avoid executing in potential sandboxes.

T1518.001
Security Software Discovery
MalwareBumblebee

Bumblebee can identify specific analytical tools based on running processes.

T1518.001
Security Software Discovery
MalwareAmadey

Amadey has checked for a variety of antivirus products.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.